Single Blog Title

This is a single blog caption

Protection of Personal Data in Administrative Law

Personal data is any information relating to an identified or identifiable natural person.

1. Constitutional and Legal Basis

The protection of personal data against administrative actions is based on Article 20, paragraph 3 (Privacy) of the Constitution. According to this provision:

“Everyone has the right to request the protection of their personal data, and such data may only be processed in cases stipulated by law or with the explicit consent of the individual.”

Aim

ARTICLE 1 - (1) The purpose of this Law is to protect the fundamental rights and freedoms of individuals, primarily the privacy of private life, in the processing of personal data, and to regulate the obligations of natural and legal persons processing personal data and the procedures and principles they must comply with.

Personal Data and Related Concepts

Personal data is any information relating to an identified or identifiable natural person. The requirements are that the person in question must be natural and that the information must be identifiable or identified.

 Processing of personal data: This refers to any operation performed on personal data, whether wholly or partly automated or non-automated, provided that it is part of a data recording system, including obtaining, recording, storing, preserving, modifying, reorganizing, disclosing, transferring, acquiring, making available, classifying, or preventing the use of such data.

Data processor: Refers to any natural or legal person who processes personal data on behalf of the data controller, based on the authorization given by the data controller

Basic Principles in the Processing of Personal Data

a) Compliance with the law and principles of honesty.

b) Being accurate and up-to-date when necessary.

c) Processing for specific, explicit and legitimate purposes.

c) They must be relevant to the purpose for which they are committed, limited, and proportionate.

d) Retention for the period stipulated in the relevant legislation or for the period necessary for the purpose for which they were processed

 

Conditions for processing personal data

ARTICLE 5 - (1) Personal data cannot be processed without the explicit consent of the data subject.

(2) In the presence of one of the following conditions, it is possible to process personal data without the explicit consent of the data subject:

  1. a) If explicitly provided for in the laws.
  2. (b) It is necessary for the protection of the life or physical integrity of the person who is unable to express their consent due to factual impossibility or whose consent is not legally valid, or for the protection of the life or physical integrity of another person.
  3. c) The processing of personal data of the parties to a contract is necessary, provided that it is directly related to the establishment or performance of the contract.

c) It must be necessary for the data controller to fulfill its legal obligations.

  1. d) It must have been made public by the person concerned themselves.
  2. e) Data processing is necessary for the establishment, exercise, or protection of a right.
  3. f) The processing of data is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.

 Relationship with Principles of Administrative Law

The principles of administrative law, which the administration must adhere to in all its actions and procedures, also apply directly to the processing of personal data

  • Legality Principle: The administration cannot collect or process personal data in any area where it is not explicitly authorized by law. The justification of "public interest" alone is not sufficient for processing data without a legal basis.

  • Proportionality and Limitation to Purpose: The administration should only collect the minimum data necessary to carry out a public service. For example, a municipality requesting unnecessary biometric data (fingerprints, etc.) from a person applying for social assistance is contrary to the principle of proportionality.

  • Good Governance Principles (Openness and Transparency): The administration is obligated to clearly inform citizens of the purpose for which it collects their data.

 The Responsibilities of the Administration as Data Controller

Ensuring Data Security

Obligation to Provide Information and Clarification

Registration in the Data Controllers Registry

Responding to Applications

 Legal Liability of the Administration (Compensation)

If the administration processes, shares, or leaks personal data unlawfully, damages arising from the administrative activity occur.

  • Service Defect: If a data leak occurs due to the administration's failure to adequately implement data security measures, this constitutes a service defect . An example is the theft of Turkish Republic identity numbers

  • Full Judicial Review: Individuals whose data has been breached and who have suffered material or moral damages as a result can file a full judicial review.

 Judicial Procedure and Competent Court

  • Actions by public officials that violate personal data may also constitute a crime under the Turkish Penal Code (Unlawfully disclosing or obtaining personal data – Article 136).

  • The competent court for annulment and full judicial review cases filed against the administration's data processing activities or the rejection of data deletion requests is the Administrative Court (Administrative Courts)

The Importance of the Lawyer

It manages the procedures and deadlines in administrative courts and handles preliminary applications. It conducts the GDPR complaint process. If a crime under Article 136 of the Turkish Penal Code has been committed, it files a criminal complaint. Based on the principle of equality of arms, it brings the client to an equal footing as a defender against public institutions.

Leave a Reply

Call Now Button